#GlobalProtect
Palo Alto Networks has silently patched an issue used by security researchers to dump cleartext PAN GlobalProtect VPN appliance passwords

github.com/t3hbb/PanGP_...
December 26, 2024 at 3:20 PM
🚨🇺🇸Alleged Sale of Unauthorized Access to GlobalProtect VPN

darkwebinformer.com/alleged-sale...
Alleged Sale of Unauthorized Access to GlobalProtect VPN
Alleged Sale of Unauthorized Access to GlobalProtect VPN
darkwebinformer.com
July 2, 2025 at 2:39 PM
The BlackBasta ransomware gang developed and used its own custom tool to brute-force enterprise firewalls and VPN remote-access products.

Named Bruted, the tool was written in PHP and could brute-force the following products (see image)

blog.eclecticiq.com/inside-brute...
March 16, 2025 at 10:41 AM
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf.
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf.
www.bleepingcomputer.com
July 21, 2026 at 10:15 AM
Real security is POC || GTFO – and XBOW agrees.

We’re releasing technical deep-dives on cool findings from our journey to the top of the HackerOne US leaderboard.

The first is a zero-day XSS in Palo Alto Networks GlobalProtect by @pwntester.bsky.social.

xbow.com/blog/xbow-gl...
XBOW – Breaking the Shield: How XBOW Discovered Multiple XSS Vulnerabilities in Palo Alto’s GlobalProtect VPN
XBOW discovered multiple cross-site scripting (XSS) vulnerabilities in Palo Alto Networks’ GlobalProtect VPN web application
xbow.com
June 24, 2025 at 7:58 PM
Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate networks.
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate networks.
www.bleepingcomputer.com
May 30, 2026 at 6:03 PM
Eine Sicherheitslücke in Palo Alto Networks Globalprotect-VPN-App ermöglicht Angreifern, Rechner vollständig zu kompromittieren. #Security
Palo Alto Globalprotect: Schadcode-Lücke durch unzureichende Zertifikatsprüfung
Eine Sicherheitslücke in Palo Alto Networks Globalprotect-VPN-App ermöglicht Angreifern, Rechner vollständig zu kompromittieren.
www.heise.de
November 27, 2024 at 1:43 PM
Palo Alto GlobalProtectの5つの脆弱性により、攻撃者がSYSTEM/ルートアクセス権を取得し、Active Directoryのパスワードを盗むことが可能に

セキュリティ研究者のマルティン・ファン・ラメスドンク氏は、パロアルトネットワークスのGlobalProtectに影響を与える5つの脆弱性を明らかにした。GlobalProtectは、Windows、macOS、Li...

...

ヴァン・ラメスドンク氏は、2026年4月初旬にパロアルトネットワークス社に責任を持って脆弱性を報告した。報告された問題のうち2つは、最終的にCVE-2026-0251として対処された。
5 Palo Alto GlobalProtect Flaws Let Attackers Gain SYSTEM/Root Access and Steal AD Passwords
Security researcher Martijn van Ramesdonk has disclosed five vulnerabilities affecting Palo Alto Networks' GlobalProtect, an enterprise VPN and endpoint agent widely used across corporate environments...
gbhackers.com
September 24, 2026 at 10:26 PM
Palo Alto kit sees massive surge in malicious activity amid mystery traffic flood
Palo Alto kit sees massive surge in malicious activity amid mystery traffic flood
GlobalProtect login endpoints targeted, sparking concern that something bigger may be brewing Malicious traffic targeting Palo Alto Networks' GlobalProtect portals surged almost 40-fold in the space of 24 hours, hitting a 90-day high and putting defenders on alert for whatever comes next.…
dlvr.it
November 20, 2025 at 11:40 AM
Nearly 24,000 IPs Target PAN-OS GlobalProtect in Coordinated Login Scan Campaign, thehackernews.com/2025/04/near...
Nearly 24,000 IPs Target PAN-OS GlobalProtect in Coordinated Login Scan Campaign
23,958 IPs scanned Palo Alto GlobalProtect portals in late March, signaling systemic recon before potential exploits.
thehackernews.com
April 1, 2025 at 12:34 PM
A major spike in malicious scanning against Palo Alto Networks GlobalProtect portals has been detected, starting on November 14, 2025.
GlobalProtect VPN portals probed with 2.3 million scan sessions
A major spike in malicious scanning against Palo Alto Networks GlobalProtect portals has been detected, starting on November 14, 2025.
www.bleepingcomputer.com
November 20, 2025 at 5:09 PM
Palo Alto GlobalProtect CVE-2024-3400 detailed analysis now public & we started to see attack attempts as of ~14 UTC today (connectivity callback tests). See: security.paloaltonetworks.com/CVE-2024-3400 for patch info/mitigation

We plan to start reporting out potentially vulnerable instances soon
CVE-2024-3400 PAN-OS: OS Command Injection Vulnerability in GlobalProtect
A command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated atta...
security.paloaltonetworks.com
April 16, 2024 at 4:20 PM
An automated campaign is targeting multiple VPN platforms, with credential-based attacks being observed on Palo Alto Networks GlobalProtect and Cisco SSL VPN.
New password spraying attacks target Cisco, PAN VPN gateways
An automated campaign is targeting multiple VPN platforms, with credential-based attacks being observed on Palo Alto Networks GlobalProtect and Cisco SSL VPN.
www.bleepingcomputer.com
December 18, 2025 at 5:27 PM
A mi no me sale. La verdad es que cuesta creer que haya gente así de hijadeputa.
GlobalProtect Portal
mi.no
February 2, 2025 at 3:10 PM
GlobalProtect is one of the most user hating bits of software in my life.
January 25, 2026 at 6:20 PM
Es sind wichtige Sicherheitsupdates für Palo Alto Networks Unternehmensbrowser Prisma und die VPN-Lösung GlobalProtect App erschienen. #Security
Palo Alto Networks: Zahlreiche Sicherheitslücken in Prisma Browser geschlossen
Es sind wichtige Sicherheitsupdates für Palo Alto Networks Unternehmensbrowser Prisma und die VPN-Lösung GlobalProtect App erschienen.
www.heise.de
August 13, 2026 at 9:39 AM
CERTFR-2025-AVI-0630: Vulnérabilité dans Palo Alto Networks GlobalProtect App
https://www.cert.ssi.gouv.fr/avis/CERTFR-2025-AVI-0630/
July 29, 2025 at 12:40 PM
🚨 Palo Alto GlobalProtect scanning surged 40X in 24hrs...a 90-day high.
2.3M login attempts from concentrated infrastructure (AS200373/AS208885).
Block these IPs now ⬇️
Palo Alto Scanning Surges 40X in 24 Hours, Marking 90-Day High
GreyNoise has identified a significant escalation in malicious activity targeting Palo Alto Networks GlobalProtect portals. Beginning on 14 November 2025, activity rapidly intensified, culminating in ...
www.greynoise.io
November 19, 2025 at 9:05 PM
Also, GlobalProtect kept failing to connect, so from 6-6:30am, WITH NO COFFEE, I fully thought I was fired.
August 4, 2026 at 6:45 PM
CVE-2026-0257 — PAN-OS GlobalProtect auth bypass, CVSS 9.1. Actively exploited. CISA KEV deadline passed June 1.

Mechanic: forged auth override cookies → unauthorized VPN session. No credentials needed.

Patch or take GlobalProtect off the perimeter. You're past due.
June 2, 2026 at 11:51 AM
Watch out...

Palo Alto Networks just issued a critical alert for an under-attack zero-day vulnerability in the PAN-OS software used in its GlobalProtect gateways

Full fix due April 14. Mitigations available now.

www.theregister.com/2024/04/12/p...
Palo Alto Networks to fix exploited GlobalProtect zero-day
Out of the PAN-OS and into the firewall, a Python backdoor this way comes
www.theregister.com
April 12, 2024 at 10:45 PM
Palo Alto GlobalProtect - RCE and Privilege Escalation via Malicious VPN Server (CVE-2024-5921)
Palo Alto GlobalProtect - RCE and Privilege Escalation via Malicious VPN Server (CVE-2024-5921)
blog.amberwolf.com
November 27, 2024 at 11:39 AM
Det jeg merker meg, er at jeg må kjøpe ny PC. Jeg har en jobb-PC, men den er bundet opp til GlobalProtect, noe som er en pest og en plage. Men greit. Må jo skille jobb og privat uansett.

Skulle bare sluppet den utgiften.
September 6, 2026 at 3:48 PM